Courseiva
Manage and secure Power BI →mediumMultiple Select

PL-300 Manage and secure Power BI Practice Question

Which TWO actions are required to enable Bring Your Own Key (BYOK) encryption for Power BI datasets? (Select exactly two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Upload the customer-managed key to Azure Key Vault

BYOK for Power BI requires the customer-managed key to be created and stored in Azure Key Vault, so option C is correct because the RSA 2048-bit (or 3072/4096-bit) key must reside in an Azure Key Vault subscription you control. Option D is also correct because, after the key exists in Key Vault, a Power BI admin must enable BYOK in the Power BI admin portal (Tenant settings) and point the tenant to that Key Vault key, granting the Power BI service the necessary wrap/unwrap permissions. Option A is not required because BYOK is a tenant-level feature available with Power BI Premium (or Fabric capacity) but assigning a specific workspace to a capacity is not the action that enables BYOK. Option B is incorrect because the key itself is never stored in Power BI admin settings; only a reference to the Key Vault key is configured there. Option E is incorrect because Microsoft Purview is not used to register the encryption key for Power BI BYOK.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the workspace to a Power BI Premium capacity

    Why it's wrong here

    BYOK requires a Premium capacity, but assigning the workspace alone does not enable it; the tenant setting must be switched on and the key stored in Azure Key Vault and assigned to the capacity. It is tempting because Premium is genuinely a prerequisite, so it appears sufficient, yet it satisfies only one condition.

  • ✗

    Store the encryption key in the Power BI service admin settings

    Why it's wrong here

    BYOK keys are created and stored in Azure Key Vault, not entered into Power BI admin settings; the tenant setting only enables BYOK and assigns permissions. It is tempting because admin portal settings govern encryption features, but the key material itself must remain in Key Vault and be referenced by the capacity.

  • ✓

    Upload the customer-managed key to Azure Key Vault

    Why this is correct

    The customer-managed key must exist in Azure Key Vault before Power BI can reference it. Uploading the key establishes the vault-held asymmetric key that Power BI later wraps around the dataset encryption key, which is the prerequisite step enabling BYOK rather than Microsoft-managed encryption.

  • ✓

    Configure the Power BI admin settings to use the key from Azure Key Vault

    Why this is correct

    BYOK requires the tenant-level admin setting that points Power BI at the specific Azure Key Vault key, binding that key to the dataset encryption. Without enabling this in the Power BI admin portal, the uploaded key remains unused and Microsoft-managed keys continue encrypting data at rest.

  • ✗

    Register the encryption key in Microsoft Purview compliance portal

    Why it's wrong here

    Microsoft Purview registers keys for compliance and information protection scenarios, not for Power BI dataset encryption. It is tempting because Purview handles data governance and key concepts, but BYOK for Power BI requires the key in Azure Key Vault, assigned to the Premium capacity via the admin portal.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.